Trojan

Trojan:Win32/Upatre!atmnm removal tips

Malware Removal

The Trojan:Win32/Upatre!atmnm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!atmnm virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre!atmnm?


File Info:

name: 2D605C9B1BE631C609FE.mlw
path: /opt/CAPEv2/storage/binaries/a227d7b426bc8dacb4b51f09b30f21a328e2946a341793773d3404c992d9be90
crc32: D03DFBC9
md5: 2d605c9b1be631c609feb5164b915170
sha1: 474cd0b794d33bb0b5e8ae39485a468f1bc73234
sha256: a227d7b426bc8dacb4b51f09b30f21a328e2946a341793773d3404c992d9be90
sha512: 1e0d577fc8f90b6a2785baef0992c5500b876ffd57d78f82b84ff7bf0891e2f693db54403291ad14d343fe6a7fcf47ab40df931fd07b9663d0ed2a39b642d255
ssdeep: 3072:1AT9HZtoeMTDApmnirZRrxrt+Uwb53blCd4Rb1:1AT95toFDAMQZRrLzd4RJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F4245A2275C0C072E173023506F8DB72567DBD724B6A99EB7798DB8D0A306C2A735763
sha3_384: 82ea2685f7c9eff605a2cc81209907a584afef7e0035389cd0df0afc54bcb65bd8967c83783d767e1cef7b18a3141515
ep_bytes: e802890000e9000000006a1468d07e42
timestamp: 2014-08-26 19:31:50

Version Info:

0: [No Data]

Trojan:Win32/Upatre!atmnm also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.CoinMiner.dm
McAfeeCoinMiner-FDM
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.CoinMiner.Win32.50931
SangforMiner.Win32.Mint_25.se2
K7AntiVirusCryptoMiner ( 005b398d1 )
K7GWCryptoMiner ( 005b398d1 )
Cybereasonmalicious.b1be63
ArcabitTrojan.Generic.D18039
VirITTrojan.Win32.BtcMine.WP
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/CoinMiner.CDD
APEXMalicious
ClamAVWin.Trojan.Coinminer-6750707-0
KasperskyHEUR:Trojan-Banker.Win32.CoinMiner.gen
BitDefenderTrojan.GenericKDZ.98361
NANO-AntivirusTrojan.Win32.CoinMiner.dejsbp
MicroWorld-eScanTrojan.GenericKDZ.98361
AvastWin32:SvcMiner-F [Trj]
TencentTrojan.Win32.CoinMiner.f
EmsisoftTrojan.GenericKDZ.98361 (B)
F-SecureTrojan.TR/BitCoinMiner.Gen4
DrWebTrojan.BtcMine.587
VIPRETrojan.GenericKDZ.98361
TrendMicroMal_CoinMiner-2
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.2d605c9b1be631c6
SophosTroj/Miner-IM
IkarusTrojan.Win32.Maener
JiangminTrojan/Generic.bbkjc
GoogleDetected
AviraTR/BitCoinMiner.Gen4
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.Graftor.PQIF@5e7luk
MicrosoftTrojan:Win32/Upatre!atmnm
ZoneAlarmHEUR:Trojan-Banker.Win32.CoinMiner.gen
GDataWin32.Trojan.Coinminer.CB
VaristW32/Coinminer.IP.gen!Eldorado
AhnLab-V3Trojan/Win.CoinMiner.R635877
Acronissuspicious
VBA32BScope.Trojan.BtcMine
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_CoinMiner-2
RisingTrojan.Maener!1.AFC8 (CLASSIC)
YandexTrojan.GenAsa!bDuAu2h40fA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetRiskware/CoinMiner
BitDefenderThetaAI:Packer.2E62405A1E
AVGWin32:SvcMiner-F [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Maener.A(dyn)

How to remove Trojan:Win32/Upatre!atmnm?

Trojan:Win32/Upatre!atmnm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment